Netscape cookies and authorization

From: Date: Tue, 05 Sep 2000 18:28:40 +0000
Subject: Netscape cookies and authorization
Groups: php.general 
Request: Send a blank email to php-general+get-15348@lists.php.net to get a copy of this message
In case you read my earlier posts, I got things working by having login.php3 only check $PHP_AUTH_USER and the individual pages check for that and the individual $USER, $STAFF, and $ADMIN cookies. For whatever reason, that works perfectly... in IE. Netscape is setting the cookie properly, as well. However, when I go to a page with <?PHP if((!($PHP_AUTH_USER)) | ($CLIENT!="true")): echo "<meta http-equiv=\"refresh\" content=\"0;url=login.php3\">"; exit; else: echo "... in Netscape, it always bounces back to login.php3 then directly to the page specified in login.php3 without asking for authorization. The odd thing is, at the top of the page it's directed to is the same php written above, but it doesn't seem to have any problem displaying that page. (The Netscape throbber doesn't stop, however) So why will it only show that page and fail on all the others in Netscape while everything works fine in IE. By the way, it's platform independent. Here's the login.php3 file: <?PHP if(!($PHP_AUTH_USER)): Header("WWW-authenticate: basic realm=Some_Realm"); Header("HTTP/1.0 401 Unauthorized"); echo "<meta http-equiv=\"refresh\" content=\"0;url=failed.html\">"; exit; else: $conn=mysql_connect("localhost","*****","*****"); mysql_select_db("******",$conn); if (!conn) {echo "An error occurred in connection.\n";exit;} $user_id=strtoupper($PHP_AUTH_USER); $password=$PHP_AUTH_PW; $result=mysql_query("SELECT * FROM clients WHERE email='$user_id' and password='$password'",$conn); if (!$result): echo "An error occurred.\n"; exit; endif; if (mysql_NumRows($result)>0): SetCookie("BRC1",$user_id,time()+0); SetCookie("BRC1",$user_id,time()+0,"/",".server.name"); SetCookie("CLIENT","true",time()+0); SetCookie("CLIENT","true",time()+0,"/",".server.name"); echo "<meta http-equiv=\"refresh\" content=\"0; url=index.php3\">"; exit; else: Header("WWW-authenticate: basic realm=Some_Realm"); Header("HTTP/1.0 401 Unauthorized"); echo "<meta http-equiv=\"refresh\" content=\"0;url=failed.html\">"; exit; endif; endif; ?> -- ------------------------------------------------------------ Adriano "Age" Manocchia am33@cornell.edu Cornell University AIM: BigRedWhat http://www.hockey.cornell.edu/age ------------------------------------------------------------ "The capacity to blunder slightly is the real marvel of DNA. Without this special attribute, we would still be anaerobic bacteria, and there would be no music." -Lewis Thomas

« previous php.general (#15348) next »